CVE-2007-3843
Linux kernel <2.6.23-rc1 - SSRF
Title source: llmDescription
The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.
References (18)
Scores
EPSS
0.0198
EPSS Percentile
83.4%
Classification
Status
draft
Affected Products (1)
linux/linux_kernel
< 2.6.22
Timeline
Published
Aug 09, 2007
Tracked Since
Feb 18, 2026